The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Web client protection settings

Prev Next

You can use the URL rate limiting technique to control the rate of URL requests to all website paths per second per IP address. The Sensor permits rate limiting of URL requests by limiting the number of the requests that go to the web. URL requests that are less than or equal to the specified rate are allowed, if the requests exceed the configured rate, an alert is raised.

You can configure to protect specific websites or apply protection to all websites. When you configure specific websites to protect against DoS attacks, the Sensor considers only those HTTP requests that contain these paths. Specifying paths optimizes the performance of the feature.

The Sensor provides you with a defense mechanism to detect the web client browser. You can use the browser detection method. This option mitigates DoS attacks originated from bots. With this option, you can send a challenge back to the user to determine if the HTTP requests are originating from valid browsers or bots. You can configure an HTML or a Javascript challenge.

The logic behind this option is that bots have limited browser functionalities. When the Sensor sends a challenge, the browser should send a legitimate response. If the response is legitimate, it is assumed that the request is originating from a valid browser. The Sensor processes the response and communicates back to the server.

If the request originated from bots, they might not understand the challenge sent by the Trellix IPS and drop the connection request. When this happens, the Sensor quarantines the host.

To understand the working of the DoS inspection options on the web client side, consider the following scenario where the Sensor is deployed in the inline mode.

  • Configure the threshold for Maximum HTTP Requests/Second Allowed to Any Website Path with a value of 50.

  • Enable Client Browser Detection.

  • Select the Browser Detection Method as JavaScript Challenge. JavaScript based challenge/response mechanism is used to detect a valid client browser.

  • Select all Website Paths to Protect.

  • Push the configuration changes to the Sensor.

  • The Sensor monitors the URL requests to websites and detects an upsurge of URL requests. Once the URL request rate is reached, the Sensor raises an alert.

  • Excess connections from the same host, exceeding any URL/second threshold, are validated by Javascript challenge mechanism. If the challenge response/refresh is successful, Sensor forwards the request to server. If the challenge response/refresh is unsuccessful by attempting 3 times, Sensor drops the request, resets the server and quarantines the host.

  • Use the show l7ddosstat command to verify the counters.